1
0
mirror of https://github.com/AvengeMedia/DankMaterialShell.git synced 2026-08-01 19:18:28 -04:00
Rafi d96559f7df core: fix security and concurrency issues found in a backend audit (#2805)
* core: fix security and concurrency issues found in backend audit

Security:
- privesc: pipe the sudo password via stdin (sudo -S) instead of
  embedding it in the command string, so it no longer appears in argv
  (readable by any local user via /proc/<pid>/cmdline or ps)
- greeter: tokenize a session .desktop Exec= line into argv and execve
  directly instead of running it through /bin/sh -c, closing a command-
  injection path via user-writable ~/.local/share/wayland-sessions
- plugins: reject path-separator/.. in plugin id/name before joining
  into a filesystem path, closing an arbitrary-directory-delete in the
  uninstall/update fallback
- keybinds/hyprland: always quote unrecognized bind actions/keys when
  writing generated Lua; only re-emit genuine round-tripped custom Lua
  verbatim (tracked via an explicit flag), closing a Lua-injection path
- desktop/mimeapps: reject newline/bracket in mime/desktop-id fields so
  they can't inject fake sections into the shared mimeapps.list

Robustness / concurrency:
- server: recover panics in the request-dispatch path so one bad
  handler can't crash the daemon and drop every client
- go-wayland: recover panics in the shared dispatch choke point so a
  malformed compositor event can't crash CLI tools / the daemon
- server: per-connection D-Bus client ID instead of a shared constant,
  fixing cross-client signal delivery and subscription teardown
- network: guard the NetworkManager device maps with a mutex (a
  concurrent map read/write here is an unrecoverable fatal error)
- cups: close the event channel on Stop() so Unsubscribe() of the last
  subscriber no longer deadlocks; allocate the fresh channel in Start()
- freedesktop: reuse the shared session conn for the settings watcher
  and tear it down in Close(), fixing a per-Manager conn+goroutine leak
- clipboard: mutex-guard lazy dbusConn creation
- geolocation: use WithMatchMember for the GeoClue2 LocationUpdated
  signal (was WithMatchSender with an interface.member string, so the
  match never fired and live location updates never arrived)
- screenshot: set failed=true on buffer/pool creation errors so the
  dispatch loop doesn't wait forever for a ready/failed that never comes

* apply code review comments

---------

Co-authored-by: bbedward <bbedward@gmail.com>
(cherry picked from commit ca89e12963)
2026-07-13 16:16:48 -04:00
2026-07-04 17:00:43 -04:00
2025-11-12 20:34:58 -05:00

DankMaterialShell

DankMaterialShell

A modern desktop shell for Wayland

Built with Quickshell and Go

Documentation GitHub stars GitHub License GitHub release Arch version AUR version (git) Ko-Fi donate

DankMaterialShell is a complete desktop shell for niri, Hyprland, MangoWC, Sway, labwc, Scroll, Miracle WM, and other Wayland compositors. It replaces waybar, swaylock, swayidle, mako, fuzzel, polkit, and everything else you'd normally stitch together to make a desktop.

Repository Structure

This is a monorepo containing both the shell interface and the core backend services:

DankMaterialShell/
├── quickshell/         # QML-based shell interface
│   ├── Modules/        # UI components (panels, widgets, overlays)
│   ├── Services/       # System integration (audio, network, bluetooth)
│   ├── Widgets/        # Reusable UI controls
│   └── Common/         # Shared resources and themes
├── core/               # Go backend and CLI
│   ├── cmd/            # dms CLI and dankinstall binaries
│   ├── internal/       # System integration, IPC, distro support
│   └── pkg/            # Shared packages
├── distro/             # Distribution packaging
│   ├── fedora/         # Fedora RPM specs
│   ├── debian/         # Debian packaging
│   └── nix/            # NixOS/home-manager modules
└── flake.nix           # Nix flake for declarative installation

See it in Action

More Screenshots
Desktop Dashboard Launcher Control Center

Installation

curl -fsSL https://install.danklinux.com | sh

One command installs DMS and all dependencies on Arch, Fedora, Debian, Ubuntu, openSUSE, or Gentoo.

Manual installation guide

Features

Dynamic Theming Wallpaper-based color schemes that automatically theme GTK, Qt, terminals, editors (vscode, vscodium), and more using matugen and dank16.

System Monitoring Real-time CPU, RAM, GPU metrics and temperatures with dgop. Process list with search and management.

Powerful Launcher Spotlight-style search for applications, files (dsearch), emojis, running windows, calculator, and commands. Extensible with plugins.

Control Center Unified interface for network, Bluetooth, audio devices, display settings, and night mode.

Smart Notifications Notification center with grouping, rich text support, and keyboard navigation.

Media Integration MPRIS player controls, calendar sync, weather widgets, and clipboard history with image previews.

Session Management Lock screen, idle detection, auto-lock/suspend with separate AC/battery settings, and greeter support.

Plugin System Extend functionality with the plugin registry.

Supported Compositors

Works best with niri, Hyprland, Sway, MangoWC, labwc, Scroll, and Miracle WM with full workspace switching, overview integration, and monitor management. Other Wayland compositors work with reduced features.

Compositor configuration guide

Command Line Interface

Control the shell from the command line or keybinds:

dms run              # Start the shell
dms ipc call spotlight toggle
dms ipc call audio setvolume 50
dms ipc call wallpaper set /path/to/image.jpg
dms brightness list  # List available displays
dms plugins search   # Browse plugin registry

Full CLI and IPC documentation

Documentation

Development

See component-specific documentation:

  • quickshell/ - QML shell development, widgets, and modules
  • core/ - Go backend, CLI tools, and system integration
  • distro/ - Distribution packaging (Fedora, Debian, NixOS)

Building from Source

Core + Dankinstall:

cd core
make              # Build dms CLI
make dankinstall  # Build installer

Shell:

quickshell -p quickshell/

NixOS:

{
  inputs.dms.url = "github:AvengeMedia/DankMaterialShell";

  # Use in home-manager or NixOS configuration
  imports = [ inputs.dms.homeModules.dank-material-shell ];
}

Contributing

Contributions welcome. Bug fixes, widgets, features, documentation, and plugins all help.

  1. Fork the repository
  2. Make your changes
  3. Test thoroughly
  4. Open a pull request

For documentation contributions, see DankLinux-Docs.

Credits

Star History

Star History Chart

License

MIT License - See LICENSE for details.

Languages
QML 63.3%
Go 29.3%
CSS 2.7%
JavaScript 1.6%
Shell 1.2%
Other 1.9%